This posting is here to collect cyber security news December 2020.
I post links to security vulnerability news with short descriptions to comments section of this article.
If you are interested in cyber security trends, read my Cyber security trends 2020 posting.
You are also free to post related links to comments.
175 Comments
Tomi Engdahl says:
Microsoft Says Suspected Russian Hackers Viewed Source Code
https://www.bloomberg.com/news/articles/2020-12-31/microsoft-says-suspected-russian-hackers-viewed-source-code
Tomi Engdahl says:
Microsoft’s Cloud Services Come Under Attack, Putting User’s Details at Risk
BY SIMON BATT
6 DAYS AGO
https://www.makeuseof.com/microsoft-cloud-under-attack-users-details-at-risk/
It’s another dark reminder of the risks of moving our personal and professional lives onto the cloud.
Tomi Engdahl says:
https://www.npr.org/2020/12/31/952436025/group-behind-alleged-russia-hack-broke-into-microsofts-internal-systems
Tomi Engdahl says:
https://www.theedgemarkets.com/article/malaysian-armed-forces-confirms-cyberattack-data-network
Tomi Engdahl says:
https://www.cyberscoop.com/finland-parliament-targeted-espionage-emails/
Tomi Engdahl says:
Vietnam targeted in complex supply chain attack
Hackers have inserted malware inside an app offered for download by the Vietnam Government Certification Authority (VGCA).
https://www.zdnet.com/article/vietnam-targeted-in-complex-supply-chain-attack/
Tomi Engdahl says:
https://threatpost.com/windows-zero-day-circulating-faulty-fix/162610/
Tomi Engdahl says:
https://cybernews.com/privacy/ghostwriter-campaign-how-my-name-was-stolen-for-an-informationoperation/
Tomi Engdahl says:
10 years in prison for illegal streaming? It’s in the Covid-19 relief bill
https://edition.cnn.com/2020/12/22/tech/illegal-streaming-felony-covid-relief-bill/index.html
Tomi Engdahl says:
A second hacking group has targeted SolarWinds systems
Some SolarWinds systems were found compromised with malware named Supernova and CosmicGale, unrelated to the recent supply chain attack.
https://www.zdnet.com/article/a-second-hacking-group-has-targeted-solarwinds-systems/
Tomi Engdahl says:
https://www.straitstimes.com/tech/tech-news/threat-from-solarwinds-hack-far-from-over-warn-experts
Tomi Engdahl says:
Cybersecurity experts hail new IoT law
The bill would increase protection for the billions of connected devices “owned or controlled by the government” in homes and businesses.
https://www.techrepublic.com/article/cybersecurity-experts-hail-new-iot-law/
Tomi Engdahl says:
NETSCAPE COMMUNICATOR AND SHA-1 WRITTEN INTO BREXIT AGREEMENT
https://hackaday.com/2020/12/28/netscape-communicator-and-sha-1-written-into-brexit-agreement/
Tomi Engdahl says:
Iranian Hackers Hit Top Israeli Defense Contractor, Data Leaked as Cyberattack Continues
Pay2Key, which has hit over 80 Israeli companies in widespread cyberattack, posts internal data of Israel Aerospace Industries employees
https://www.haaretz.com/israel-news/tech-news/.premium-iranian-hackers-hit-israel-aerospace-industries-leak-data-as-cyberattack-continues-1.9387283
Tomi Engdahl says:
FBI says hackers are breaking into home cameras to watch SWAT teams respond to bogus emergency calls
https://www.washingtontimes.com/news/2020/dec/30/fbi-says-hackers-are-breaking-into-home-cameras-to/
Tomi Engdahl says:
Microsoft Says Suspected Russian Hackers Viewed Source Code
https://www.bloomberg.com/news/articles/2020-12-31/microsoft-says-suspected-russian-hackers-viewed-source-code
Software maker discovers unusual activity on internal accounts
Company says no customer data or services accessed by hackers
Tomi Engdahl says:
New Golang-based Crypto worm infects Windows and Linux servers
https://securityaffairs.co/wordpress/112825/malware/golang-based-worm-windows-linux.html
Experts from Intezer discovered a new and self-spreading Golang-based malware that targets Windows and Linux servers.
Tomi Engdahl says:
The Great iPwn
Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit
https://citizenlab.ca/2020/12/the-great-ipwn-journalists-hacked-with-suspected-nso-group-imessage-zero-click-exploit/
Tomi Engdahl says:
Ledger Crypto Data Breach – 270,000 Wallet Owners Data has been leaked
https://threatit.com/articles/ledger-crypto-wallets-data-breach-270000-wallet-data-leaked/
Tomi Engdahl says:
Thieves burglarize Russia’s nuclear war ‘doomsday’ plane
https://www.cnn.com/2020/12/09/europe/russian-doomsday-plane-scli-intl/index.html
Tomi Engdahl says:
https://hackaday.com/2020/12/06/leaking-data-by-ultrasound/
Tomi Engdahl says:
As Understanding of Russian Hacking Grows, So Does Alarm
https://www.nytimes.com/2021/01/02/us/politics/russian-hacking-government.html
Those behind the widespread intrusion into government and corporate networks exploited seams in U.S. defenses and gave away nothing to American monitoring of their systems.
Tomi Engdahl says:
Insecure wheels: Police turn to car data to destroy suspects’ alibis
Looser privacy standards for vehicle data are a treasure chest of data for law enforcement.
https://www.nbcnews.com/tech/tech-news/snitches-wheels-police-turn-car-data-destroy-suspects-alibis-n1251939
For more than two years, Kalamazoo County sheriff’s detectives investigated French’s murder without making any arrests. Then, according to police records obtained by NBC News, one of the detectives learned of an emerging field — digital vehicle forensics — which focuses on extracting the treasure trove of data stored in an automobile’s onboard computers.
Tomi Engdahl says:
NSO used real people’s location data to pitch its contact-tracing tech, researchers say
Researchers say NSO’s use of real data “violated the privacy” of thousands of unwitting people.
https://techcrunch.com/2020/12/30/nso-fleming-data-location/
Tomi Engdahl says:
Ticketmaster will pay $10 million for hacking rival ticket seller
It used stolen login credentials at a company summit
https://www.theverge.com/2020/12/30/22206955/ticketmaster-songkick-crowdsurge-hacking-deferred-prosecution-fine
Ticketmaster has agreed to pay $10 million for breaking into a competitors’ network. The company and its parent Live Nation admitted to hiring a former employee from rival ticket seller CrowdSurge, then using his knowledge — including old usernames and passwords — to learn CrowdSurge’s inner workings and “cut [the company] off at the knees.”